easyMultiple Choice
PT0-002 Practice Question: Should be included in the appendix section of a…
Which of the following should be included in the appendix section of a penetration testing report?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Raw tool output and scan results
Appendices contain supporting details like scope, methodology, and raw tool output.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Raw tool output and scan results
Why this is correct
Correct — raw tool output and scan results are exactly the kind of bulky, unprocessed data that belongs in an appendix. They provide supporting evidence and reproducibility for the findings discussed in the report body, without cluttering the narrative. An appendix is the standard location for this material, along with configuration files, endpoint lists, and detailed command output that stakeholders can consult if needed.
- ✗
Remediation steps for each finding
Why it's wrong here
Incorrect — remediation steps are actionable guidance that must appear in the technical findings section, directly appended to each vulnerability description. The appendix is reserved for raw supporting artifacts, not for instructions on how to fix a problem. Placing remediation there would force the reader to flip to the back of the report while evaluating each finding, breaking the logical flow.
- ✗
Executive summary
Why it's wrong here
Incorrect — the executive summary is a front-matter section, not an appendix. It is written for management and contains a concise overview of the test's purpose, scope, and overall risk posture, giving high-level context before the technical details. The appendix, by contrast, is back matter intended for readers who want to verify the underlying raw data, so an executive summary there would be out of place and inaccessible.
- ✗
Key findings and overall risk rating
Why it's wrong here
Incorrect — key findings and the overall risk rating are the core content of the executive summary, where they are presented as prioritized, high-level business risks. These items are meant to be seen early in the report by executives who need a quick snapshot, not buried in an appendix. The appendix holds the detailed, unfiltered evidence that supports those findings, not the summary of them.
Go deeper
Related to this question
Learn chapter
Red Team Exercises vs Penetration Tests
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
Key term
Scope
In IT, scope defines the boundaries, goals, and deliverables of a project, assessment, or engagement, specifying what is included and what is excluded.
About these practice questions
This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.